CVE-2026-53862

EUVD-2026-37164
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.2 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
openclawopenclaw
𝑥
< 2026.5.12
openclawopenclaw
2026.5.12:beta1
openclawopenclaw
2026.5.12:beta2
openclawopenclaw
2026.5.12:beta3
openclawopenclaw
2026.5.12:beta4
openclawopenclaw
2026.5.12:beta5
openclawopenclaw
2026.5.12:beta6
openclawopenclaw
2026.5.12:beta7
openclawopenclaw
2026.5.12:beta8
𝑥
= Vulnerable software versions